Junglewise Threat Intelligence

danielgatis rembg SSRF and CORS misconfiguration in HTTP server

Severity: medium · CVSS 4.3 · Published 2026-04-10

Executive brief

rembg is a tool used to remove backgrounds from images. Its server component contains vulnerabilities that could allow an attacker to trick the server into accessing internal network resources or bypass security restrictions on web requests. This could lead to the exposure of sensitive images or data hosted on the organization's private internal network.

Technical details

The rembg server component contains two primary security flaws. First, the `/api/remove` endpoint is vulnerable to Server-Side Request Forgery (SSRF) because it fetches images from user-provided URLs without validating if the destination is a public or private IP address. Second, the server implements a weak Cross-Origin Resource Sharing (CORS) policy that reflects all origins and sets `allow_credentials` to true. An attacker can leverage these issues by hosting a malicious website that, when visited by a user, sends cross-site requests to the rembg server to probe or exfiltrate images from the internal network. These issues were addressed in version 2.0.75 by validating IP addresses and hardening CORS settings.

Affected products

  • danielgatis rembg < 2.0.75

Timeline

  • 2026-04-09: patched: Fixes committed and version 2.0.75 released.
  • 2026-04-10: advisory: GitHub Security Advisory published.

References

Related threats